2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-47436MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MantraBrain Yatra ...
CVE-2022-47423MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.
CVE-2022-47137MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPManageNinja LLC Ninja Tables plugin <= 4.3.4 version...
CVE-2022-27856MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Atlas Gondal Export All URLs plugin <= 4.1 versions.
CVE-2022-46861MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Zia Imtiaz Custom Login Page Styler for WordPress plug...
CVE-2022-46819MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Continuous announcement scroller plugin ...
CVE-2022-46817MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Flyzoo Flyzoo Chat plugin <= 2.3.3 versions.
CVE-2022-33961MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WaspThemes Visual CSS Style Editor plugin <= 7.5.8 ver...
CVE-2022-32970MEDIUM5.4Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Themify Themify Portfolio Post plugin <= 1.2.4 versio...
CVE-2022-4008MEDIUM5.5In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv...
CVE-2022-36330HIGH8.1A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remo...
CVE-2022-23818HIGH7.5Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest ...
CVE-2022-46864MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Umair Saleem Woocommerce Custom Checkout Fields Editor Wit...
CVE-2022-46858MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Amin A.Rezapour Product Specifications for Woocommerce plu...
CVE-2022-46844MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
CVE-2022-46822MEDIUM6.1Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in JC Development Team WooCommerce JazzCash Gateway Plugin pl...
CVE-2022-41640MEDIUM5.4Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in Rymera Web Co Wholesale Suite plugin <= 2.1.5 ver...
CVE-2022-4537MEDIUM6.5The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and ...
CVE-2022-48389MEDIUM4.4In modem control device, there is a possible out of bounds write due to a missing bounds check. This could lead to local...
CVE-2022-48388HIGH7.8In powerEx service, there is a possible missing permission check. This could lead to local escalation of privilege with ...
CVE-2022-48387MEDIUM4.4the apipe driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial...
CVE-2022-48386MEDIUM4.4the apipe driver, there is a possible use after free due to a logic error. This could lead to local denial of service wi...
CVE-2022-48385MEDIUM4.4In cp_dump driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denia...
CVE-2022-48384HIGH7.8In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no ...
CVE-2022-48383HIGH7.8.In srtd service, there is a possible missing permission check. This could lead to local escalation of privilege with no...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now